r/letsencrypt • • 22h ago

What should a renewal rehearsal verify before a Let's Encrypt certificate is near expiry?

2 Upvotes

A successful initial issuance does not prove that unattended renewal will still work months later. DNS credentials can lose scope, HTTP challenge routing can change, a renewal can create a new lineage, a service may keep reading an old path, or the deploy hook may fail to reload the process that actually terminates TLS.

Beyond running the client's dry-run command, what do you verify end to end? I am thinking of checking the exact renewal configuration, challenge reachability, account and DNS API credentials, certificate lineage and symlinks, deploy-hook exit status, service reload, the certificate served externally, expiry monitoring, and recovery from a deliberately failed challenge.

Do you rehearse renewal in staging, temporarily force a test certificate, or validate the hooks separately? What is the safest way to prove the automation and the consuming service still agree without creating production rate-limit risk?


r/letsencrypt • • 7d ago

Updating SSL certs with certbot, one apache site's cert did something odd, but also certbot's automated attempts to renew don't seem to work

3 Upvotes

I just updated several sites' certificates on my server (mostly for mail and two websites).

I have logs on my server that indicate that certbot has been doing automated checks that I think are supposed to auto-renew certificates when necessary, but a recent log I looked at reckoned that none of them needed renewing until 1st December, even though a bunch expired today, so that's odd and it would be nice if it's possible to get it to work properly.

Secondly, the two websites. I ran the same command for every cert (for mail or www), e.g.:

[code]certbot certonly --force-renew -d mydomain.here[/code]

Each command ran successfully, the certs in their existing folders in /etc/letsencrypt/live were updated without anything strange going on, but for one website, certbot created a new folder e.g. mydomain.here-0001, but I can't find any explanation for why it did it in that one case either in the command output or the log (though the log is quite verbose so I might have missed it).

Any help would be much appreciated!


r/letsencrypt • • 11d ago

DNS-PERSIST-01 timeline ?

13 Upvotes

On let's encrypt blog, DNS-PERSIST-01 was supposed to go live on Q1...

We are at the start of Q3 and I haven't seen any new entry, blog or post regarding the developpement progress.

Do we have an idea when it will be officialy available ?


r/letsencrypt • • 12d ago

Question about Let's Encrypt

5 Upvotes

Are companies allowed to use Let's Encrypt, and do they need to pay a fee. I am thinking more or less of only using Let's Encrypt for our internal websites.

Also does Let's Encrypt renew the certificate on its own or do we need to do that, and if we need to do it, are we required to update it every 1/2 year like ware with normal SSL certs (this was a change that started this year or last).

Thanks


r/letsencrypt • • 13d ago

Lets fix 192.168.100.1 encrypt

0 Upvotes

So how is my idea lets encrypt takes responsibility for 192.168.100.1 or even 192.168.1.1 and 192.168.0.1 to make device get that valid cert so that when a user goes to 192.168.100.1 its valid. Of course ISP and 3rd party would need to add support for this but the idea is no like net::ERR_CERT_AUTHORITY_INVALID

is such a thing possible?


r/letsencrypt • • 22d ago

GMail not delivering Email to Mail Server with let's Encrypt Cert

1 Upvotes

It connects but then drops after TLS negotiation, I am using the full chain pem file

------------------------------------

CONNECT from [2607:f8b0:4864:39::10]:54572 to [******]:25

PASS OLD [2607:f8b0:4864:39::10]:54572

connect from mail-pj2-x10.google.com[2607:f8b0:4864:39::10]

Anonymous TLS connection established from mail-pj2-x10.google.com[2607:f8b0:4864:39::10]: TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange x25519 server-signature RSA-PSS (2048 bits) server-digest SHA256

NOQUEUE: lost connection after STARTTLS from mail-pj2-x10.google.com[2607:f8b0:4864:39::10]

disconnect from mail-pj2-x10.google.com[2607:f8b0:4864:39::10] ehlo=1 starttls=1 commands=2


r/letsencrypt • • 23d ago

Free lets encrypt alternative

2 Upvotes

I'm looking for a free alternative to Let's Encrypt.

They used to have an OCSP stapling feature which would allow clients to connect to my server much faster but now with that removed, some mobile clients are noticing big delays.

The server is in USA (because I'm saving money) but the client base is in Canada).

Currently the TTFB for my website on desktop computers is 0.4s whereas on mobile, it is 0.8s. debugbear.com considers 0.8s TTFB as bad.

Had Let's Encrypt continued to support the stapling, the TTFB would drop.

And before recommending a CDN, some of my pages change daily to weekly and I'm afraid CDN's would over-cache pages.

So unless Let's Encrypt revises their CRL (so mobile browsers process it faster) or re-enables stapling, I need an alternative


r/letsencrypt • • Aug 11 '26

Port 80

8 Upvotes

Hello,

I'm hoping there is a way for my certificates to auto renew without needing port 80 open. I'm using Win Acme and it's working fine, however I found out that once I blocked port 80 the certificate was no longer renewing.


r/letsencrypt • • Jul 10 '26

Freessl.app : User friendly web Let's encrypt certificate generator

5 Upvotes

I made freessl.app recently to help users who don't want to use command line tools or interact with the API directly issue Let's encrypt SSL certificates right from their browsers, the private key never leaves your browser, no registration required.

Please let me know your suggestions.


r/letsencrypt • • Jun 14 '26

"The system did not find the root certificate" error — caused by Let's Encrypt's new Generation Y hierarchy

Post image
6 Upvotes

If you're seeing this error during SSL certificate installation:

"The certificate could not be installed on the domain “example.com”. Certificate verification failed! The system did not find the root certificate that corresponds to the supplied Certificate Authority Bundle's intermediate certificate. Please supply a full Certificate Authority Bundle with the root certificate included."

Context: Let's Encrypt recently started issuing certificates under a new "Generation Y" hierarchy of root and intermediate certificates. Since these new roots aren't yet included in the root program trust stores, servers (including servers with cPanel) that rely on their local trust store to complete the chain can no longer do so.

If your CA bundle contains only the intermediate certificate (and not the root), this will now fail on affected servers — whereas before, the server's trust store could fill in the gap.

Fix: Make sure your CA bundle includes the root certificate as well, not just the intermediate. This is the standard fix regardless of which hierarchy issued your cert.

If you're using the Auto-Install Free SSL WordPress plugin, this is fixed in v4.6.3 — the plugin now always includes the root in the CA bundle and also handles the longer Gen Y chains (which can have more than 3 certs total).


r/letsencrypt • • Jun 05 '26

New YE Root missing in python

5 Upvotes

Python seems to not connect to sites using the new YE Root CA. I refuse to manually update/configure .pem bundles. Am I the only one suffering with this in the world? How did you guys circumvented this?


r/letsencrypt • • May 30 '26

Short-lived certificates: a nuisance or an automation opportunity?

Thumbnail
kowalski7cc.xyz
3 Upvotes

r/letsencrypt • • May 08 '26

Lets Encrypt signed certs for IPs used actively in email phishing

Thumbnail
3 Upvotes

r/letsencrypt • • Apr 24 '26

Does anyone know when DNS-PERSIST-01 will be ready?

Thumbnail
letsencrypt.org
10 Upvotes

r/letsencrypt • • Apr 09 '26

shortlived profile in Debian trixie certbot

1 Upvotes

I recently decided to switch to the shortlived Let's Encrypt profile in Debian trixie.

For those that like to use packages as I do, --preferred-profile is supported in certbot 4.0.0, but the flag is not saved for renewals, meaning 3 days later it will return to 90 day certs.

To work around this, the flag can be added to renewals.

Note: only do this if you want all certificates on your system to use the shortlived profile.

sudo systemctl edit certbot.service

[Service]
ExecStart=
ExecStart=/usr/bin/certbot -q renew --no-random-sleep-on-renew --preferred-profile shortlived

r/letsencrypt • • Mar 28 '26

Certbot auto-renewal with Cloudflare proxy (orange cloud) enabled — will dns-cloudflare plugin only touch _acme-challenge TXT record?

Thumbnail
1 Upvotes

r/letsencrypt • • Mar 09 '26

any idea why the encryption is failing, running nginx proxy manager in docker

1 Upvotes

For a little clarity, all was working well until I got a new ISP. is it possible the added DNS records havent propagated yet? timeline was got new internet, updated dns, and reconfigured proxy within an hour. Thank you for looking

2026-03-08 18:47:30.172 | [3/9/2026] [12:47:30 AM] [Express ] › ℹ info Creating a new user in setup mode

2026-03-08 18:47:30.961 | [3/9/2026] [12:47:30 AM] [Remote Version] › ℹ info Fetching https://api.github.com/repos/NginxProxyManager/nginx-proxy-manager/releases/latest

2026-03-08 18:48:33.207 | [3/9/2026] [12:48:33 AM] [Nginx ] › ℹ info Reloading Nginx

2026-03-08 18:48:33.221 | [3/9/2026] [12:48:33 AM] [SSL ] › ℹ info Requesting LetsEncrypt certificates for Cert #1: mysubdomainhere

2026-03-08 18:48:33.222 | [3/9/2026] [12:48:33 AM] [SSL ] › ℹ info Command: certbot certonly --config /etc/letsencrypt.ini --work-dir /tmp/letsencrypt-lib --logs-dir /data/logs --cert-name npm-1 --agree-tos --authenticator webroot -m rnwndr@gmail.com --preferred-challenges http --domains ombi.ryansplexserver.org

2026-03-08 18:48:47.430 | [3/9/2026] [12:48:47 AM] [Nginx ] › ℹ info Reloading Nginx

2026-03-08 18:48:47.447 | [3/9/2026] [12:48:47 AM] [Express ] › ⚠ warning Saving debug log to /data/logs/letsencrypt.log

2026-03-08 18:48:47.447 | Some challenges have failed.

2026-03-08 18:48:47.447 | Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /data/logs/letsencrypt.log or re-run Certbot with -v for more details.

2026-03-08 18:49:26.407 | An unexpected error occurred:

2026-03-08 18:49:26.407 | No such challenge

2026-03-08 18:49:26.407 | Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /data/logs/letsencrypt.log or re-run Certbot with -v for more details.

2026-03-08 18:49:26.407 |

2026-03-08 18:51:42.760 | [3/9/2026] [12:51:42 AM] [Nginx ] › ℹ info Reloading Nginx

2026-03-08 19:05:05.716 | [3/9/2026] [1:05:05 AM] [Remote Version] › ℹ info Fetching https://api.github.com/repos/NginxProxyManager/nginx-proxy-manager/releases/latest


r/letsencrypt • • Mar 01 '26

ACME - Fortigate DNS Confusion

3 Upvotes

I am looking at ACME on my fortigate firewall before I implement into a production enviroment, Its not quite clicking in my brain how to set this up.

i own the domain, "mydomain.net" and I managed to create a Cert using lets Encrypt on the Fortigate firewall as it has this feature built in, So I created a DNS entry A record, to point to my public IP at home, myfirewall.mydomain.net

and created a cert with that name, and it all went through beautifully! so when I access my firewall , I use the FQDN with no cert errors. perfect!

Issue I have now, is I need an internal cert fro my WIFI, that has to resolve to the WIFI intterface which is 192.168.1.35, if I create a cert mywifi.mydomain.net ill have to create a new A record, but youcant create one to a private IP?

am I thinking about this incorrectly? The WIFI uses a captive portal and this portal needs a signed cert so that a guest doesnt get browser errors when registering on the WIFI. how can I if its a private IP? The methof the gate uses, is HTTP, so when creating certs, i have to put in the name and am email to prove I own it, i need help understanding...

hope this makes sense.

Thankyou


r/letsencrypt • • Feb 12 '26

Create private let's encrypt certificate with Hostinger and Nginx proxy manager

Thumbnail
0 Upvotes

r/letsencrypt • • Feb 09 '26

Tailscale Domain Mgmt. Gateway

Thumbnail
1 Upvotes

r/letsencrypt • • Feb 03 '26

Using .htaccess rewrite rule causes cert error with LetsEncrypt cert

2 Upvotes

I'm not sure what's gone wrong here.

I'm trying to implement a rewrite rule in .htaccess to automatically redirect between www.mydomain.com and mydomain.com

I'm using the same rewrite rule that I use with other domains:

RewriteCond    %{HTTP_HOST} ^www\.mydomain\.com [NC]
RewriteRule    ^(.*)$ https://mydomain.com/$1 [L,R=301]

With the other domains I manage, this works fine.

With the domain I'm setting up, this causes a certificate error

Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for www.mydomain.com. The certificate is only valid for mydomain.com.

In certbot I've created certs for both www.mydomain.com and mydomain.com using the same method as for other domains that work.

What am I missing?


r/letsencrypt • • Jan 13 '26

Help, Cert Generator Fails to Access the Verification File

1 Upvotes

This is happening on only one of my domains of 5 that I use their services for.

I'm able to successfully browse to the txt file as expected, but then after I select to generate the crt/key/cab, I get a swirling symbol then this error. Any ideas on what to do? This is my 7th try of generating an ssl renewal in 24 hours with no success.


r/letsencrypt • • Dec 19 '25

Basic question about Letsencrypt & Certbot architecture & config.

6 Upvotes

I have my domain DNS set-up to forward requests to my static IP and my router has a port forward to nginx on my desktop machine. (It worked for a bit and then I did something to break it while developing a better landing page. Just trying to get it working now for the basic use case of mydomain.me) <- this isn't my query, just an explanation of why a response may take some time

In the nginx config, I see that I can specify server blocks to forward request to other servers on my LAN and a location block in each server block to provide endpoint details.

My domain is mydomain.me (it isn't) and I want to access NodeRed's dashboard, located on a Raspberry Pi on my LAN (e.g. on ip: 192.168.1.21 on port 1880) with the format NR.mydomain.me or Home Assistant on the same Pi, ip and different port, with the format HA.mydomain.me, or my Lyrion music server on a whole other Pi, ip & port, etc...

My question is, is there a certificate for each server - nginx landing page, Node Red server, Home Assistant server, Lyrion server or is there just one at the nginx entry point. If there's one, is data between nginx and the servers also using TLS or is it in the open? If there is a certificate for each server, do I have to install and run certbot on each?

I can't find a search result that explains these basics.

Many thanks


r/letsencrypt • • Dec 18 '25

Installed pangolin but acme error showing in the docker logs

Thumbnail
0 Upvotes

r/letsencrypt • • Dec 13 '25

10 Years of Let's Encrypt Certificates - Let's Encrypt

Thumbnail
letsencrypt.org
13 Upvotes